Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 01 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 31 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in Aider-AI Aider 0.86.3. This affects the function requests.get of the file api_docs.py of the component AWS EC2 Metadata Endpoint. The manipulation leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. It is suggested to install a patch to address this issue. The pull request to fix this issue awaits acceptance. | |
| Title | Aider-AI Aider AWS EC2 Metadata Endpoint api_docs.py requests.get server-side request forgery | |
| First Time appeared |
Aider-ai
Aider-ai aider |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:aider-ai:aider:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aider-ai
Aider-ai aider |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-01T13:30:03.353Z
Reserved: 2026-05-30T16:21:45.507Z
Link: CVE-2026-10177
Updated: 2026-06-01T13:29:57.828Z
Status : Deferred
Published: 2026-05-31T11:16:46.537
Modified: 2026-06-01T15:15:37.293
Link: CVE-2026-10177
No data.
OpenCVE Enrichment
Updated: 2026-05-31T12:00:13Z